PT-2026-57234 · Rclone · Rclone

CVE-2026-54572

·

Published

2026-07-09

·

Updated

2026-09-04

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions rclone versions prior to 1.74.4
Description When using the -l/--links flag, the software serializes symlinks as .rclonelink text objects and recreates them on a local destination without validating the target. This allows an attacker-controlled remote source to plant an escaping symlink, causing subsequent object writes to occur outside the intended destination directory with attacker-chosen contents.
Recommendations Update to version 1.74.4.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-RCLONE-2026-54572
CVE-2026-54572
GHSA-CF44-9PGV-M4XC
GO-2026-6191
OPENSUSE-SU-2026:11241-1
OPENSUSE-SU-2026:21436-1
OPENSUSE-SU-2026:21761-1

Affected Products

Rclone